The XSS inside your favorite iOS app
Attack Techniques & MethodsYesterday, 13:42
A WKWebView without explicit download handling can render a response marked
Content-Disposition: attachment instead of downloading or blocking it. When a service hosts user uploads on a trusted origin, an attacker can upload HTML and distribute a direct file URL that becomes active content inside an application's embedded browser.The default behavior demonstrated in the article is sandboxed HTML and CSS rendering. That is sufficient for trusted-origin UI spoofing and state-changing GET requests through elements such as
<img>. JavaScript execution is not universal: the authors observed full XSS only in specific application and response combinations.Firefox and Firefox Focus for iOS confirmed the broader mechanism. Firefox ignored the attachment disposition, while Focus also rendered binary MIME types; Mozilla tracked the issues as
CVE-2025-55030 and CVE-2025-55032 and fixed both. The article also reports affected social in-app browsers, wallet dApp browsers, and PlayStation browsers, but not every listed application has a published independent advisory.Exploitation requires attacker-controlled file contents on a useful origin and a victim opening the direct URL in an affected embedded browser. Applications can prevent the transition by handling
decidePolicyFor navigationResponse and choosing .download or .cancel for attachment or unsupported MIME responses.Article: https://v12.sh/blog/webkit
Vulnerabilities
Researchers
Vendors
Products